Back to home

Privacy Policy

We collect what we need to make the platform work, and nothing else. Plain English on what that means in practice.

Last updated August 2026.

Who this applies to

This policy covers everyone who uses Common Elements, Inc. (“CE,” “we,” “us”): board members, association staff, management company employees, vendors, attorneys, insurance professionals, and anyone visiting our public pages. Common Elements operates from Florida and serves U.S.-based community associations and the businesses around them. It also covers people who have never created an account: association officers and board members whose names we compile from government records, described under “Public-record and directory data” below.

What we collect

The data we collect falls into three buckets:

  • Account information you give us: email address, full name, organization name, role within that organization, and (optionally) phone number, biography, avatar, professional credentials (LCAM, license numbers, attorney bar admission), and contact-visibility preferences.
  • Content you create on the platform: forum posts, RFPs, proposals, reviews, direct messages, follow relationships, and any documents you upload.
  • Operational data we collect automatically: authentication tokens, session timestamps, IP addresses, browser metadata, error reports, and basic usage events (which pages were visited, which actions were taken). We do not run advertising trackers and do not sell or share this data with ad networks.

Public-record and directory data

Separately from the account and content data above, Common Elements compiles a directory of community associations and their officers from government records: state corporate and homeowners-association filings (for example, Florida’s Division of Corporations and DBPR license records), county recorder and property-appraiser records, and similar public filings. This is how an association gets a page on Common Elements even when no one from that association has signed up.

For officers and board members, the free platform, the forum, and the public directory show name, role, and the association’s own filed address only. Personal email and phone numbers for officers and board members, where we have them, come from external sources, never from a person’s own Common Elements account, and appear only in the paid data product used by vendors and other subscribers. They are never published on a free or public surface.

If you are an officer or board member, whether or not you have a Common Elements account, and want to know what we hold about you from public records, or want it corrected or removed, email privacy@commonelements.com.

Browser extension (Common Elements Insight)

Common Elements Insight is an optional Chrome extension. It surfaces HOA and condo association data on real estate listing pages you visit, and, only after you explicitly opt in, collects a small set of factual details from those listings to improve our association database. It is independent and not affiliated with or endorsed by Zillow, Redfin, Realtor.com, or Trulia.

What the extension collects (only with your consent): factual listing details: property address, ZIP, approximate coordinates, list price, bedrooms/bathrooms, living area, HOA fee and frequency, amenities, property type, the association/community name shown on the page, and the address of the listing page itself. These are read from the page’s own public structured data.

What it never collects: listing photographs, written listing descriptions or agent remarks, your browsing history, the identity of which listings you personally viewed as a profile of you, your keystrokes, or data from any site other than the supported listing pages. The extension runs only on listing pages you open yourself; it does not crawl, pre-fetch, or navigate on its own.

Collection is off by default. Nothing is sent until you grant consent in the extension, and you can turn it off at any time from the extension’s settings, which immediately stops all collection. We use the collected facts solely to build and improve the association database that the platform and extension surface back to users.

Anonymous usage statistics: separately from the listing facts above, the extension records which steps it reaches so we can tell when it breaks. These records say things like “installed”, “panel opened”, “a listing was recognised on Zillow”, “no association matched” and whether an expected field was missing. They are tied to a random identifier created when you install the extension, which is not derived from you, your device, or your Google account, and is destroyed when you remove the extension. They never include addresses, listing content, page URLs, or anything you type. You can turn this off in the extension’s settings.

Our use of information received from the Common Elements Insight extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. We use the data described above only to provide and improve the association-data features of the extension and platform. We do not sell it, use it for advertising, or transfer it to determine creditworthiness or for lending purposes.

Mobile application

The Common Elements app for iOS and Android collects the same account information and platform content described above. A handful of things are specific to a phone. Every one of them is optional, is requested only when you use the feature that needs it, and the app keeps working if you decline.

  • Precise location: used only to geotag a site walkthrough you are recording. It is read while the app is open, never in the background, and the walkthrough saves normally if you decline. We do not build a location history and we do not track your movement between walkthroughs.
  • Camera and photo library: used when you attach a photo, set a profile picture, scan a governing document, or ask for AI help drafting an RFP scope. The app opens the camera or the picker only when you tap the control that needs it, and it reads only the images you select.
  • Microphone and speech recognition: used to dictate meeting notes and motion text. Transcription runs on your device. If a device cannot do on-device recognition, the app tells you dictation is unavailable there rather than sending your audio to a speech service. The recognized text becomes part of the note you are writing; the audio itself is never uploaded or stored by us.
  • Document scanning: text recognition on pages you scan runs on your device using the operating system text recognizer. The recognized text is uploaded when you save the document, the same as text you type in yourself.
  • Calendar: write-only. When you choose to sync a meeting, the app adds that event to a Common Elements calendar on your device. It never reads, stores, or transmits the events already on your calendar.
  • Push notifications: if you allow them, the device push token is stored alongside your account so we can deliver the notifications you turned on. It is a device identifier, not an advertising identifier.

Crash and performance monitoring: the app uses Sentry to report crashes and slow screens so we can fix them. A report includes the error, the screens you visited just before it, and basic device and app-version details. We configure Sentry not to attach your name, email, or other account details to these reports.

Product analytics: the app also records a small, fixed set of product events, such as viewing an association page, following an association, running a search, or working with an RFP, so we can tell which features people actually use. These events are tied to your account while you’re signed in, or to a random identifier stored on your device before that. The app carries no advertising, attribution, or data-broker SDK of any kind, we do not sell this data, and it is never used to track you across other companies’ apps or sites. The app does check our update service for app updates, which is delivery, not measurement.

You can delete your account from inside the app under Settings. That runs the same deletion described under “Your rights” below rather than sending you to the website.

How we use it

We use the data above to operate the platform, authenticate users, route notifications, deliver email, prevent abuse, investigate security incidents, debug errors, and improve the product. Membership status determines what you can see on the platform. That’s enforced at the database level, not by UI hiding.

We do not sell personal information, and we do not share it with advertisers. We use AI only in the limited way described under “AI features” below, and never to train an outside provider’s general models.

AI features

We use AI in a small number of places, and only when you ask for it. In each case the content you submit is sent to our AI provider (Anthropic) through our own servers. Our provider credentials stay on our servers and are never shipped inside the mobile app. These are the features:

  • Ember, the in-product assistant: answers questions about associations, vendors, and statutes, and, when you ask, about your own account, by calling tools against Common Elements’ data and, where relevant, your own RFPs, proposals, messages, and notifications under the same permissions that apply everywhere else on the platform. It cites what it drew from. Actions that would change your data, such as drafting an RFP or sending a message, are never taken automatically; you review and approve each one first. We log Ember conversations so we can review whether its answers are accurate and improve them.
  • Document analyzer: the text of a governing document you upload, read and summarized against the relevant statutes, and used to extract basic facts such as association name, dates, and unit count. Governing documents can contain personal data such as owner names, addresses, and unit identifiers, so we treat this the same as the rest of your content.
  • Budget and reserve study import: a budget or reserve study file you choose to import, read so its figures can be turned into a structured draft you review and edit.
  • Site photo assist: a photograph you take or pick while drafting an RFP scope, described so the scope can be pre-filled. The app captures these photos with EXIF metadata disabled, so no embedded location or camera detail travels with the image.

Content submitted to these features is processed only to return your result. It is not used to train the provider’s models, and the provider retains it only transiently under our contract. The AI extracts, describes, and summarizes; it does not give legal advice or decide whether anything in your document is enforceable.

Service providers

To run the platform we share specific data with a small set of vetted service providers, each under contract:

  • Supabase (PostgreSQL hosting, authentication, file storage). All account and platform content data.
  • Vercel (web hosting, edge networking). Request metadata and edge cache.
  • Resend (transactional email delivery). Email addresses and message bodies for notifications and platform emails.
  • Stripe (billing, when paid plans launch). Customer record and payment metadata; no card numbers ever touch our servers.
  • Sentry (error and performance monitoring, web and mobile). Stack traces, request metadata, and crash reports. Personally identifying details are scrubbed where feasible on the web and excluded by configuration on mobile.
  • PostHog (product analytics, web and mobile). Which pages and features you use, tied to your account while you’re signed in. Used to understand usage and fix broken flows, not for advertising. We do not sell this data.
  • Anthropic (AI processing). Your conversations with Ember, including the account records Ember reads to answer you, the text of a document you choose to analyze, the budget or reserve study files you choose to import, and the site photographs you submit for RFP scope assist. Sent only to return your result. Not used to train the provider’s models; retained only transiently under our contract. See “AI features” above.

Cookies and similar technology

We use cookies that are strictly necessary to keep you signed in and to remember your in-product preferences (such as your active organization context and notification preferences). We do not set third-party advertising cookies.

Retention

We keep your account data for as long as your account is active. Forum posts, RFPs, proposals, reviews, and messages persist for the operational lifetime of the platform so that audit trails remain intact for boards and counsel. That’s a fiduciary expectation, not a marketing one. Server logs and error reports are retained for up to 90 days. If you close your account, we retain content you authored in shared contexts (forum posts, RFPs, reviews) but disassociate it from your identifying account information unless we’re legally required to keep it linked.

Your rights

You can delete your own account at any time from Settings on the web or in the app, or by emailing privacy@commonelements.com. Deleting your account starts a 30-day window during which it can still be restored; after that window, it and your personal data are permanently removed. If you’re the sole admin of an organization, you’ll need to transfer that role or close the organization first. You can request a copy of your personal data, correct inaccuracies, or restrict processing the same way. If you don’t have a Common Elements account but appear in our public-record directory data as an officer or board member, see “Public-record and directory data” above for how to reach us. If you’re a California resident, you have additional rights under the California Consumer Privacy Act; if you’re based in the EEA or UK, GDPR rights apply. We respond to verified requests within 30 days.

Security

Account access requires authentication. Database row-level security ensures users only see what their organization membership entitles them to. Production traffic is HTTPS-only with strict transport security; HSTS, frame-busting, and a content security policy are enforced at the application edge. We rotate credentials, scan dependencies for known vulnerabilities, and document our incident response procedure.

No system is impervious. If we discover a security incident that affects your data, we’ll tell you what happened, what we did about it, and what you should do, without spin.

Children

Common Elements is not directed at children under 13 and we do not knowingly collect data from them. If you believe a minor has created an account, contact us and we’ll delete it.

Changes to this policy

We’ll update this page when our practices change. Material changes are announced via in-app notification and email at least 30 days before they take effect. The “last updated” date at the top of this page reflects the most recent revision.

Contact

Common Elements, Inc.
Florida, USA
privacy@commonelements.com